Open Trust Infrastructure
Trust that depends on a single vendor's database is not trust, it is dependency. Open Trust Infrastructure is the open side of Staple's approach: keep signed provenance attached to the data itself as it crosses APIs, pipelines, and models, using a published protocol anyone can verify against rather than a log only Staple can read. It is the standard, and the open tooling, behind the commercial Audit Readiness capability in Staple's Trust Layer.
Provenance That Travels With The Data
Data loses verifiable context every time it crosses an API, a pipeline, or a model. The origin is severed in transit, the compliance obligations attached to it do not travel, and the record of what was verified and by which system has to be rebuilt after the fact. Metastructured Data closes that gap by attaching a cryptographically signed record to the data itself, either as a self-contained envelope or embedded inside the file, so the next system, or an auditor, can confirm what a value is, where it came from, and that it has not changed, without calling back to Staple.
What The Envelope Carries
The signed envelope is assembled from four layers, each bound to the others. Provenance records the source document, captured as a SHA-256 hash of the original file, along with the model that read it, the operator, and the timestamp. Processing records the pipeline and model versions and the region the work ran in. Custody records the chain of events, every edit, reviewer, and completion, drawn from the existing audit trail. Residency records where the data is allowed to live and move, as machine-readable tags such as region-only or no-transit. The envelope is canonicalized to a stable byte form and signed with an Ed25519 key, so verification is exact and any downstream party can perform it.
Valid Versus Trusted
There is a distinction the protocol makes explicit. Anyone can generate a key and produce a technically valid signature, but a valid signature from an unknown key says nothing about who signed it. Trust requires a key that has been endorsed through the MSD Network, which gives a chain back to a known root. So a verifier answers two separate questions: is this signature valid, and is the signer trusted. Both checks run without setup and work offline, because the proof lives in the artifact rather than on a server you must reach.
Verify Anywhere, Enforce At Egress
Because the trust is embedded and signed, two things become possible that a separate audit log cannot offer. First, independent verification: any third party, a customer, an auditor, or a regulator, can verify a Staple output through a public verifier without a Staple account, confirming signature validity, that the source hash matches, and that residency is consistent. Second, enforcement at the boundary: residency rules can be checked at the moment data tries to leave a region, so a document tagged for one jurisdiction is blocked from routing to another rather than being caught in a review months later. The same standard therefore satisfies the questions a supervisor actually asks, whether under a tax authority that cross-references invoices, a financial regulator that demands input integrity for AI-assisted decisions, or a regime that classifies the workflow itself as high risk.
The Protocol, The SDK, And The Network
• The protocol is an open specification for signed, verifiable structured data, using content-addressed structure and Ed25519 signatures so any change breaks the signature.
• The SDK is an open-source toolkit that signs a dictionary or a file into a self-contained envelope, or embeds the proof inside it, and verifies both offline, published at github.com/msd-protocol.
• The network adds optional identity, endorsement, and key-status services that turn a locally valid signature into a trusted one, at the MSD Network.
Why Open Matters
An open standard can be verified by the parties who need to trust it, regulators, auditors, and counterparties, without taking Staple's word for it or integrating Staple just to check a signature. It also means the trust record outlives any single vendor relationship, which is exactly what a regulator wants to hear and what a platform building for the long term should want too. The full standard is documented on the Metastructured Data page.
Open Maturity, Stated Plainly
The open protocol and SDK are early stage, and the SDK is described as early alpha on the protocol site. Some capabilities are not yet supported, and anyone considering a dependency should read the roadmap first. Staple's commercial platform is production and audited; the open SDK is not at parity with it. These are different things and we do not blur them. Nothing here implies production standardization or external adoption beyond available evidence.
Explore The Standard
Read the full standard on the Metastructured Data page, explore the code at github.com/msd-protocol, or open the MSD Network. For the audited capability inside the product, see Audit Readiness.
Related Topics
See Staple process your documents
Book a 30-minute demo with a document processing specialist.
Not ready yet?
Take your time to decide.